Splunk Search

Splunk Search
Community Activity
elusive
I am indexing some logs and I see some events are filled with "\x00" while some other events are indexed correctly.
by elusive Splunk Employee Splunk Employee in Splunk Search 08-09-2016
5 6
5
6
dperry
I'm importing a file into Splunk and the file always has these fields: Date (07/25/16 ) | Time (01:12:04) | Message...
by dperry Communicator in Splunk Search 08-09-2016
0 6
0
6
prakash007
Looking for a regex in 612,200(threadDuration) and 3(no.of.Threads) for the log message below... WSVR0605W: Thread “...
by prakash007 Builder in Splunk Search 08-09-2016
1 2
1
2
_dave_b
Hello. I'm trying to construct a footer containing my app's version in a dashboard. The footer resides in a differe...
by _dave_b Communicator in Splunk Search 08-09-2016
0 5
0
5
simona2121
I want to know the exact difference between sma and avg. Also, can someone pls provide detailed description of trend...
by simona2121 Path Finder in Splunk Search 08-09-2016
2 3
2
3
Javo222
I've messed my Splunk system up a bit and some jobs or searches (I don't remember) are continuously running (every mi...
by Javo222 Path Finder in Splunk Search 08-09-2016
0 3
0
3
Gayathirik
How to detect if there is a growing number of a particular type of event? It could indicate “flapping” on the Exchang...
by Gayathirik Path Finder in Splunk Search 08-09-2016
0 4
0
4
plucas_splunk
Given public transit log data of the form: 2016-08-01 13:34:03 GMT vehicle_id="1234" stop_id="5678" I would like t...
by plucas_splunk Splunk Employee Splunk Employee in Splunk Search 08-08-2016
0 1
0
1
basanthp
The below is the windows security logs Message field data. The Security_ID field is splunk identified and contains 2 ...
by basanthp Path Finder in Splunk Search 08-08-2016
1 7
1
7
wuwangjun
Hi Guys, I have the below XML in a log file: I can't get the the name attribute via "path="Customer{@value}")" patt...
by wuwangjun New Member in Splunk Search 08-08-2016
0 6
0
6
sureshwalmart
Hi This is my current Splunk search: index=pqaestore source="/log/jboss_jmx_stats.log" | dedup host | rex field=_ra...
by sureshwalmart Explorer in Splunk Search 08-08-2016
0 1
0
1
sridharreddy
Hi Somesh, How My search: transaction part| timechart values(duration) as duration,values(rollno) as rollno Resu...
by sridharreddy New Member in Splunk Search 08-08-2016
0 1
0
1
cegoes
Pastebin of search.log: http://pastebin.com/aAzw697G Job inspect statistics: 0.00 command.fields 15 197...
by cegoes Explorer in Splunk Search 08-08-2016
0 3
0
3
pradjswl
I have tried the following search, but it doesn't work correctly. Option 1) Using following join command, it works g...
by pradjswl Explorer in Splunk Search 08-08-2016
0 5
0
5
thomasaporter
Is there anyway to manually import threat intelligence downloads for internal servers (offline from the internet)? Y...
by thomasaporter Explorer in Splunk Search 08-08-2016
0 4
0
4
JoshuaJohn
I scoured the internet, but came along a few different attempts and I tried, but the results were not what I was look...
by JoshuaJohn Contributor in Splunk Search 08-08-2016
0 1
0
1
dbcase
Hi, I have one that I've worked around until now.....  The scenario is: Row is URI /a /b /c /d /e /f Column is I...
by dbcase Motivator in Splunk Search 08-08-2016
0 6
0
6
daishih
I created a two panel dashboard I want to use to see "block" OR "deny" firewall records from three of our security de...
by daishih Path Finder in Splunk Search 08-08-2016
0 3
0
3
rajiv_abraham
Hi, When I search using the Python API and provide earliest_time and latest_time, I guess it is an inclusive range, ...
by rajiv_abraham Explorer in Splunk Search 08-08-2016
0 1
0
1
mansel_scheffel
Hi, I am trying to set up a bunch of summary indexes and was wondering if there are any best practices to follow? Is...
by mansel_scheffel Explorer in Splunk Search 08-08-2016
0 3
0
3
Chrstover
I have two sources with different data in each except one common column in each sourcetype called "DeviceName". In s...
by Chrstover New Member in Splunk Search 08-08-2016
0 4
0
4
mehwishw
Hi, I want to use the result of one search, and then use this result in another search to put it in the same chart. ...
by mehwishw New Member in Splunk Search 08-08-2016
0 3
0
3
chandra61446
I have table like below Backup_Status BackupDate Servers Success 07/16/2016 archiveserver1 Failed ...
by chandra61446 New Member in Splunk Search 08-08-2016
0 2
0
2
jimrobson
I have a stacked column chart that shows 2 values in each column. One of these values tends to be very small (0-3 eve...
by jimrobson Explorer in Splunk Search 08-08-2016
1 4
1
4
pkeller
Looking for a way to report on whether a lookup table is exported to all apps by using a rest search. Assuming the l...
by pkeller Contributor in Splunk Search 08-08-2016
0 2
0
2
Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Request for Professional Development: Attending .conf26

Winning Over the Boss: Your Pass to .conf26 conf26 is going to be here before you know it. If don't already ...